Akheon23 / marketlicensing

Automatically exported from code.google.com/p/marketlicensing
Apache License 2.0
0 stars 0 forks source link

LVL Easily patched out of applications #13

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
What steps will reproduce the problem?
1. Full description 
http://www.androidpolice.com/2010/08/23/exclusive-report-googles-android-market-
license-verification-easily-circumvented-will-not-stop-pirates/

Please provide any additional information below.

Possibly adding some kind of integrity check to the dex file will fix this?

Original issue reported on code.google.com by jus...@androidpolice.com on 23 Aug 2010 at 5:12

GoogleCodeExporter commented 9 years ago
Checking the integrity of the APK (and with it the classes.dex) is quite easy 
possible by the app itself by comparing the package-signature with a fixed one. 
I more fret about an app (you could download on certain sites...) which patches 
out the LVL from the dex-file in the dalvik-cache! Yes, you need a rooted 
phone, but who with cracked-apps doesn't have?

Original comment by hendrik....@googlemail.com on 5 Feb 2012 at 8:49